System and method for cloud-based network control
By encrypting and signing packets using TCP tunnel client programs in a cloud-based network, the time-consuming and complexity problems of cloud-based network device control and monitoring are solved, and fast, secure and reliable device management is achieved.
Patent Information
- Application Number
- CN202380062002.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-08-26
- Filing Date
- 2023-08-22
- Publication Date
- 2025-06-13
AI Technical Summary
Control, monitoring and security of cloud-based network devices The management and monitoring tasks are time-consuming and difficult due to geographical and logical separation.
The network access device uses the TCP protocol to establish an encrypted connection with the host, and uses the TCP tunnel client program to encrypt, sign and segment the packets, achieving fast, easy and secure control and monitoring of isolated network devices.
Fast, secure and reliable control and monitoring of isolated network equipment is achieved, reducing the time-consuming and complexity of management and monitoring.
Smart Images

Figure CN120153609A_ABST
Abstract
Description
[0001] Claims of Priority and Incorporation by Reference
[0002] This application claims the benefit of U.S. Provisional Patent Application 63 / 401,373, filed Aug. 26, 2022, the disclosure of which is hereby incorporated by reference in its entirety. Technical Field
[0003] This disclosure generally relates to computer networking, and more particularly, to systems and methods for cloud-based control of network devices. Background Art
[0004] Cloud-based networks include multiple devices or nodes that can have the ability to communicate with each other. These devices or nodes can reside on isolated networks in geographically separated regions. Due to the time-consuming nature of logging into the only device residing on geographically and logically separated networks to perform management and monitoring tasks, firewall and addressing issues, the control, monitoring, and security of these devices or nodes can be difficult and time-consuming.
[0005] Accordingly, there is a need in the art for a system that enables devices to securely form encrypted connections and enables fast, easy, and secure control and monitoring of devices that may reside on isolated networks. Summary of the Invention
[0006] Systems and methods for cloud-based control and monitoring of network devices are provided. The subject matter provides hardware and software for setting up and controlling host devices on a network. An encrypted connection is established between a network access device and a host using the Transmission Control Protocol (TCP). The network access device determines that packets to be transmitted to the host will be routed via a TCP tunnel client program. Based on this determination, the network access device sends the packets to the TCP tunnel client program. The TCP tunnel client program encrypts, signs, and fragments the packets, and the network access device sends the encrypted packets to a remote endpoint associated with the host using TCP.
[0007] This summary is an overview of some of the teachings of this application and is not intended to be an exclusive or exhaustive treatment of the subject matter. More details about the subject matter can be found in the detailed description and the appended claims. The scope of the invention is defined by the appended claims and their legal equivalents. Brief Description of the Drawings
[0008] In the accompanying drawings, which are not necessarily drawn to scale, like reference numerals may describe similar components in different views. The drawings generally illustrate, by way of example and not limitation, the various embodiments discussed in this patent application.
[0009] Figure 1 An example of a system for cloud-based control of network devices according to one embodiment of the subject matter is shown.
[0010] Figure 2 A flowchart showing an example of a method for cloud-based control of network devices according to one embodiment of the subject matter is shown.
[0011] Figure 3 An example of a digital communication port configured to communicate over a network according to one embodiment of the subject matter is shown.
[0012] Figure 4 A block diagram showing components of a machine capable of reading instructions from a machine-readable medium (e.g., a machine-readable storage medium) and performing any one or more of the methods discussed herein according to some example embodiments is shown. Detailed Description
[0013] The following detailed description of the subject matter refers to the subject matter in the accompanying drawings, which illustrate specific aspects and embodiments in which the subject matter may be practiced. The embodiments are described in sufficient detail to enable those skilled in the art to practice the subject matter. References to "an embodiment," "one embodiment," or "various" embodiments in this disclosure do not necessarily refer to the same embodiment, and such references contemplate more than one embodiment. The following detailed description is illustrative and should not be considered limiting in nature. The scope of the subject matter is defined by the appended claims and the full scope of legal equivalents to those claims.
[0014] Figure 1Illustrates an example of a system for cloud-based control of network devices according to an embodiment of the present subject matter. In various embodiments, the system 100 may include a network access device 110 configured to establish an encrypted connection with a host 120 using the Transmission Control Protocol (TCP) 130. The network access device 110 may determine that packets to be transmitted to the host 120 will be routed via the TCP tunnel client program 114. Based on this determination, the network access device 110 sends the packets to the TCP tunnel client program 114. The TCP tunnel client program 114 encrypts 115, signs, and fragments 116 the packets, and the network access device 110 sends the encrypted packets to the remote endpoint associated with the host 120 using TCP 130.
[0015] In various embodiments, the network access device may include a switch. In various embodiments, the network access device may include a device having the ability to create a virtual network interface. In various embodiments, the network access device may include a TUN device. In various embodiments, the network access device may include a virtual Internet Protocol point-to-point interface having the ability to process network packets and configured to connect to a host or server running a TCP tunnel program. In various embodiments, the network access device TCP tunnel program may be configured to connect to a host or server running a TCP tunnel server program. In various embodiments, the network access device TCP tunnel program may be configured to connect to a host or server running a TCP tunnel server program that is only reachable via a dedicated TCP port. In various embodiments, the TCP tunnel server includes a cloud-based server or any other device that can create a virtual network interface. In various embodiments, the network access device TCP tunnel program may be configured to connect to a host or server running a TCP tunnel server program that is only reachable via TCP port 443.
[0016] In various embodiments, the network access device TCP tunnel client program transmits packets through a load balancing module. In various embodiments, the load balancing module includes load balancing logic. Such load balancing logic can be based on parameters that include, but are not limited to, one or more of geography, latency, host health, or host server response time. Additionally, the load balancing logic directs one or more packets to a particular host running a TCP tunnel server program, enabling multiple hosts to run the TCP tunnel server program in parallel. In various applications, the load balancing module enables: connecting different devices executing the TCP tunnel client program to different hosts based on parameters that include, but are not limited to, one or more of latency, host health, geographic region, or host server response time. Those skilled in the art will recognize other parameters that can be used without departing from the scope of the subject matter after reading and understanding this disclosure.
[0017] After establishing an encrypted connection between the device running the TCP tunnel client program as Figure 1 mentioned and the device running the TCP tunnel server program, the devices can interact with the network access device 110 using an API that can be accessed on the network access device via a connection 130 through HTTP methods described by the RFC2616 protocol. Devices that do not run the TCP tunnel client or TCP tunnel server program can interact with the device running the TCP tunnel client program by: sending an identifier as part of an HTTP or HTTPs interaction to a publicly accessible API endpoint hosted on the device running the TCP tunnel server program, and the API endpoint verifies the entity sending the HTTP or HTTPs interaction can communicate with the network access device 110 via the connection 130 by validating the identifier included in the HTTP or HTTPs interaction. These identifiers can be valuable as they can centrally control different levels of access to the network access device 110 running the TCP tunnel client program. HTTP or HTTPs interactions made by entities that do not run the TCP tunnel client or TCP tunnel server program can be logged to a database by a program monitoring the publicly accessible API endpoint. This enables entities to record interactions with the device running the TCP tunnel client program.
[0018] In various embodiments, the network access device includes a TCP tunnel client. In some embodiments, the network access device includes a switch connected to a TCP tunnel server (e.g., host 120), which can be a server in the cloud. According to various embodiments, the network access device 110 includes a user space 111 and a kernel space 117. The user space 111 includes an application 112, and the kernel space 117 has tun0 118 and eth0 119. In various embodiments, the host 120 includes a user space 121 and a kernel space 127. The user space 121 includes an application 122, and the kernel space 127 has tun0 129 and eth0 128. In various embodiments, the host 120 (e.g., a server in the cloud or a cloud-based server) may also include a TCP tunnel-server program 124 for reconstituting 126 and decrypting 125 messages from the network access device 110.
[0019] Various embodiments of the present subject matter use TCP as the underlying communication protocol to establish an encrypted connection between the network access device 110 and the host 120 or a server. In various embodiments, TCP provides a number of benefits as compared to other communication protocols. For example, TCP requires less overhead and administrative effort to manage the communication or set up a dashboard, and can reuse the connection without having to re-establish it. In some embodiments, TCP allows connections to be established on more networks as compared to other protocols, since a commonly used protocol, Hypertext Transfer Protocol secure (HTTPs), uses TCP. In various embodiments, TCP can use Secure Sockets Layer (SSL) as the default encryption protocol, which is a standard commonly used for network communication. TCP is a connection-oriented protocol, such that the communicating devices should establish a connection before transmitting data and should close the connection after transmitting the data. TCP is reliable because it uses an Acknowledgement (ACK) in various embodiments to ensure that the data is delivered to the destination router. TCP provides a broad error-checking mechanism by providing flow control and data acknowledgement. The sequencing of data is a feature of the Transmission Control Protocol (TCP), which means that packets arrive at the receiver in order and lost packets can be retransmitted in TCP. TCP has a variable length header of (20 to 60) bytes. Additionally, TCP is heavyweight and uses handshakes such as SYN, ACK, and SYN-ACK. Further, TCP is used by protocols such as HTTP, HTTPs, FTP, SMTP, and Telnet. In various embodiments, a TCP connection is a byte stream and has a relatively low overhead. Other communication protocols can be used without departing from the scope of the present subject matter.
[0020] Figure 2A flowchart illustrating an example of a method for cloud-based control of network devices according to an embodiment of the present subject matter. According to various embodiments, method 200 includes, at step 202, an application delivering a packet to an Operating System (OS). At step 204, the OS routes the packet to a TCP tunnel client program, and at step 206, the packet is forwarded to a kernel tun device. At step 208, the kernel tun device forwards the packet to a TCP tunnel-client process, and at step 210, the TCP tunnel-client process encrypts and signs the packet and the packet is sent by the kernel tun device to the address of a remote endpoint running a TCP tunnel-server program. At step 212, in various embodiments, the kernel tun device forwards the encrypted packet to the remote endpoint for reverse processing.
[0021] Figure 3 Illustrates an example of a digital communication port or client 300 configured to communicate over a network according to an embodiment of the present subject matter. In various embodiments, client 300 includes a network stack, and client 300 may include a user space 310 and a kernel 320. In various embodiments, user space 310 may include an application 312 and a TCP tunnel-client program 314. In various embodiments, kernel 320 may include a TCP / IP stack 322, a routing table 324, a tun / tap Network Interface Card (NIC) 326, and a hardware NIC 328. In some embodiments, hardware NIC 328 may communicate over a network such as an Ethernet network 330. According to various embodiments, client 300 may include a Resistor-Inductor (RL) switch or a temperature sensor. Other types of client devices may be used without departing from the scope of the present subject matter.
[0022] Modules, Components, and Logic
[0023] Certain embodiments are described herein as including logic or multiple components, modules, or mechanisms. A module may constitute a software module (e.g., code included on a machine-readable medium) or a hardware module. A “hardware module” is a tangible unit capable of performing certain operations and may be configured or arranged in a certain physical manner. In various example embodiments, one or more computer systems (e.g., a stand-alone computer system, a client computer system, or a server computer system) or one or more hardware modules of a computer system (e.g., a processor or a group of processors) may be configured by software (e.g., an application or a portion of an application) to operate as a hardware module that performs certain operations as described herein.
[0024] In some embodiments, the hardware module may be implemented mechanically, electronically, or in any suitable combination thereof. For example, the hardware module may include dedicated circuitry or logic that is permanently configured to perform certain operations. For example, the hardware module may be a dedicated processor such as a Field-Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC). The hardware module may also include programmable logic or circuitry that is temporarily configured by software to perform certain operations. For example, the hardware module may include software executed by a general-purpose processor or other programmable processor. Once configured by such software, the hardware module becomes a particular machine (or a particular component of a machine) uniquely customized to perform the configured functions and is no longer a general-purpose processor. It will be appreciated that the decision of whether to implement the hardware module mechanically in dedicated and permanently configured circuitry or in temporarily configured (e.g., software-configured) circuitry may be driven by cost and time considerations.
[0025] Accordingly, the phrase "hardware module" should be understood to include a tangible entity, i.e., an entity that is physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate or perform certain operations described herein in a certain manner. As used herein, "hardware-implemented module" refers to a hardware module. Considering embodiments in which the hardware module is temporarily configured (e.g., programmed), it is not necessary to configure or instantiate each of the hardware modules at any given time. For example, in the case where the hardware module includes a general-purpose processor that is configured by software to become a dedicated processor, the general-purpose processor may be configured as different dedicated processors (e.g., including different hardware modules) at different times. The software accordingly configures a particular one or more processors to, for example, constitute a particular hardware module at one time and to constitute different hardware modules at different times.
[0026] Hardware modules can provide information to other hardware components and receive information from other hardware modules. Thus, the described hardware modules can be considered to be communicatively coupled. In cases where multiple hardware modules are present, communication can be achieved through signal transmission between or among two or more hardware modules (e.g., via appropriate circuitry and buses). In embodiments where multiple hardware modules are configured or instantiated at different times, communication between such hardware modules can be achieved, for example, by storing information in a memory structure accessed by the multiple hardware modules and retrieving the information from the memory structure. For example, one hardware module can perform an operation and store the output of the operation in a memory device to which it is communicatively coupled. Then, another hardware module can access the memory device at a later time to retrieve and process the stored output. Hardware modules can also initiate communication with input or output devices and can operate on resources (e.g., a collection of information).
[0027] The various operations of the example methods described herein can be performed, at least in part, by one or more processors that are temporarily configured (e.g., by software) or permanently configured to perform the relevant operations. Whether temporarily or permanently configured, such processors can constitute processor-implemented modules that operate to perform one or more of the operations or functions described herein. As used herein, a "processor-implemented module" refers to a hardware module implemented using one or more processors.
[0028] Similarly, the methods described herein can be at least in part processor-implemented, where a particular one or more processors are examples of hardware. For example, at least some of the operations of the method can be performed by one or more processors or processor-implemented modules. Additionally, one or more processors can also operate to support the execution of the relevant operations in a "cloud computing" environment or as a "Software as a Service" (SaaS) operation. For example, at least some of the operations can be performed by a group of computers (as an example of machines including processors), where the operations can be accessed via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., an Application Program Interface (API)).
[0029] The execution of certain operations can be distributed among processors, deployed not only within a single machine but across multiple machines. In some example embodiments, the processors or processor-implemented modules can be located in a single geographical location (e.g., in a home environment, an office environment, or a server farm). In other example embodiments, the processors or processor-implemented modules can be distributed across multiple geographical locations.
[0030] Machine and Software Architecture
[0031] In some embodiments, the modules, methods, applications, etc. described herein are implemented in the context of a machine and an associated software architecture. The following sections describe representative architectures applicable to the disclosed embodiments. Figures 1 to 3 The software architecture is used in conjunction with the hardware architecture to create devices and machines customized for a particular purpose. For example, a particular hardware architecture coupled with a particular software architecture will create a mobile device such as a mobile phone, a tablet device, etc. Slightly different hardware and software architectures may result in smart devices for the "Internet of Things". And another combination results in a server computer within a cloud computing architecture. Not all combinations of such software and hardware architectures are presented herein because those skilled in the art can readily understand how to implement the present invention in contexts different from the disclosure contained herein.
[0032] Example Machine Architecture and Machine - Readable Medium
[0033]
[0034] Figure 4 is a block diagram showing the components of a machine 400 capable of reading instructions from a machine - readable medium (e.g., a machine - readable storage medium) and performing any one or more of the methods discussed herein. Specifically, Figure 4 shows a graphical representation of an example form of a machine 400 in the form of a computer system within which instructions 416 (e.g., software, program, application, applet, app, or other executable code) can be executed to cause the machine 400 to perform any one or more of the methods discussed herein. For example, the instructions can cause the machine to execute Figure 2 the flowchart of Figure 1 Figure 3 and Figure 3one or more of the devices and / or components. The instructions transform a general-purpose, unprogrammed machine into a particular machine programmed to perform the described and illustrated functions in the described manner. In an alternative embodiment, machine 400 operates as a stand-alone device or may be coupled (e.g., networked) to other machines. In a networked deployment, machine 400 may operate in a server-client network environment as either a server machine or a client machine, or as a peer machine in a peer-to-peer (or distributed) network environment. Machine 400 may include, but is not limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a personal digital assistant (PDA), or any machine capable of sequentially or otherwise executing instructions 416 specifying actions to be taken by machine 400. Further, although only a single machine 400 is shown, the term "machine" shall also be taken to include a collection of machines 400 that individually or jointly execute instructions 416 to perform any one or more of the methods discussed herein.
[0035] Machine 400 may include a processor 410, a memory 430, and I / O components 450, which may be configured to communicate with each other, for example, via a bus 402. In an example embodiment, processor 410 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a radio-frequency integrated circuit (RFIC), other processors, or any suitable combination thereof) may include, for example, a processor 412 and a processor 414 that may execute instructions 416. The term "processor" is intended to include multi-core processors that may include two or more independent processors (sometimes referred to as "cores") that may execute instructions simultaneously. Although Figure 4Shows multiple processors, but machine 400 can include a single processor with a single core, a single processor with multiple cores (e.g., multi-core processing), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0036] Memory / storage device 430 can include memory 432 (e.g., main memory or other memory storage device) and storage unit 436, and processor 410 can access both memory 432 and storage unit 436, for example, via bus 402. Storage unit 436 and memory 432 store instructions 416 embodying any one or more of the methods or functions described herein. Instructions 416 may also reside entirely or partially within memory 432, within storage unit 436, within at least one of processors 410 (e.g., within a cache memory of the processor), or in any suitable combination thereof during execution by machine 400. Thus, memory 432, storage unit 436, and the memory of processor 410 are examples of machine-readable media.
[0037] As used herein, "machine-readable medium" means a device capable of storing instructions and data temporarily or permanently, and may include, but is not limited to: Random-Access Memory (RAM), Read-Only Memory (ROM), buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage devices (e.g., Erasable Programmable Read-Only Memory (EEPROM)), and / or any suitable combination thereof. The term "machine-readable medium" should be considered to include a single medium or multiple media capable of storing instructions 416 (e.g., a centralized or distributed database or associated cache memory and servers). The term "machine-readable medium" should also be considered to include any combination of the following media or multiple media: the media capable of storing instructions (e.g., instructions 416) executable by a machine (e.g., machine 400) such that the instructions, when executed by one or more processors (e.g., processor 410) of machine 400, cause machine 400 to perform any one or more of the methods described herein. Thus, "machine-readable medium" refers to a single storage device or apparatus, as well as a "cloud"-based storage system or storage network including multiple storage devices or apparatuses. The term "machine-readable medium" does not include a signal per se.
[0038] The I / O component 450 may include various components for receiving input, providing output, generating output, transmitting information, exchanging information, capturing measurement results, and so on. The specific I / O component 450 included in a particular machine will depend on the type of the machine. For example, a portable machine such as a mobile phone will likely include a touch input device or other such input mechanism, while a headless server machine will likely not include such a touch input device. It will be recognized that the I / O component 450 may include Figure 4 many other components not shown in Figure 4 . The I / O component 450 is grouped according to function merely for the sake of simplifying the following discussion, and the grouping is in no way restrictive. In various example embodiments, the I / O component 450 may include an output component 452 and an input component 454. The output component 452 may include visual components (e.g., displays such as plasma display panels (PDPs), light emitting diode (LED) displays, liquid crystal displays (LCDs), projectors, or cathode ray tubes (CRTs)), acoustic components (e.g., speakers), haptic components (e.g., vibration motors, resistance mechanisms), other signal generators, and so on. The input component 454 may include alphanumeric input components (e.g., keyboards, touchscreens configured to receive alphanumeric input, optoelectronic keyboards, or other alphanumeric input components), point-based input components (e.g., mice, touchpads, trackballs, joysticks, motion sensors, or other pointing instruments), tactile input components (e.g., physical buttons, touchscreens that provide the location and / or force of a touch or touch gesture, or other tactile input components), audio input components (e.g., microphones), and so on.
[0039] In additional example embodiments, the I / O component 450 may include various other components such as a biometric component 456, a motion component 458, an environmental component 460, or a positioning component 462. For example, the biometric component 456 may include components for detecting expressions (e.g., hand expressions, facial expressions, voice expressions, body postures, or eye tracking), measuring biometric signals (e.g., blood pressure, heart rate, body temperature, sweating, or brain waves), identifying people (e.g., voice recognition, retina recognition, facial recognition, fingerprint recognition, or electroencephalogram-based recognition), etc. The motion component 458 may include an acceleration sensor component (e.g., an accelerometer), a gravity sensor component, a rotational sensor component (e.g., a gyroscope), etc. The environmental component 460 may include, for example, an illumination sensor component (e.g., a photometer), a temperature sensor component (e.g., one or more thermometers for detecting ambient temperature), a humidity sensor component, a pressure sensor component (e.g., a barometer), an acoustic sensor component (e.g., one or more microphones for detecting background noise), a proximity sensor component (e.g., an infrared sensor for detecting nearby objects), a gas sensor (e.g., a gas detection sensor for detecting the concentration of hazardous gases to ensure safety or for measuring pollutants in the atmosphere), or other components that can provide indications, measurement results, or signals corresponding to the surrounding physical environment. The positioning component 462 may include a position sensor component (e.g., a Global Position System (GPS) receiver component), an altitude sensor component (e.g., an altimeter or barometer for detecting the air pressure from which altitude can be obtained), an orientation sensor component (e.g., a magnetometer), etc.
[0040] Various techniques can be used to implement communication. The I / O component 450 may include a communication component 464 that is operable to couple the machine 400 to the network 480 or the device 470 via the couplings 482 and 472, respectively. For example, the communication component 464 may include a network interface component or other suitable devices for interfacing with the network 480. In additional examples, the communication component 464 may include a wired communication component, a wireless communication component, a cellular communication component, a Near Field Communication (NFC) component, a Bluetooth component (e.g., Bluetooth Low Energy), components, and other communication components that provide communication via other modalities. The device 470 may be another machine or any of various peripheral devices (e.g., a peripheral device coupled via a Universal Serial Bus (USB)).
[0041] In addition, the communication component 464 may detect an identifier or may include a component operable to detect an identifier. For example, the communication component 464 may include a Radio Frequency Identification (RFID) tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, multi-dimensional barcodes such as Quick Response (QR) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF413, Ultra Code, UCC RSS-2D barcodes, and other optical codes), or an acoustic detection component (e.g., a microphone for identifying an audio signal of a tag). Additionally, various information may be obtained via the communication component 464, such as a location obtained via Internet Protocol (IP) geolocation, a location obtained via signal triangulation, a location obtained via detecting an NFC beacon signal that may indicate a specific location, and so on.
[0042] transmission medium
[0043] In various example embodiments, one or more portions of the network 480 may be an ad hoc network, an intranet, an extranet, a Virtual Private Network (VPN), a Local Area Network (LAN), a Wireless LAN (WLAN), a Wide Area Network (WAN), a Wireless WAN (WWAN), a Metropolitan Area Network (MAN), the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a Plain Old Telephone Service (POTS) network, a cellular telephone network, a wireless network, A network, other types of networks, or a combination of two or more such networks. For example, network 480 or a portion of network 480 may include a wireless or cellular network, and the coupling 482 may be a Code Division Multiple Access (CDMA) connection, a Global System for Mobile communications (GSM) connection, or other types of cellular or wireless couplings. In this example, the coupling 482 may implement any of a variety of data transmission technologies, such as Single Carrier Radio Transmission Technology (1xRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, the third Generation Partnership Project (3GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standards, other data transmission technologies defined by various standards-setting organizations, other long-distance protocols, or other data transmission technologies.
[0044] Instructions 416 can be sent or received over network 480 via a network interface device (such as the network interface component included in communication component 464), using a transmission medium and any one of a number of well-known transmission protocols (such as Hypertext Transfer Protocol (HTTP)). Similarly, instructions 416 can be sent or received using a transmission medium via a coupling 472 to device 470 (e.g., a peer-to-peer coupling). The term "transmission medium" shall be considered to include any non-transitory medium that is capable of storing, encoding, or carrying instructions 416 for execution by machine 400, and includes digital or analog communication signals or other non-transitory media to facilitate the communication of such software.
[0045] Other descriptions and examples
[0046] Example 1 is a computer-implemented method for controlling a network device. The method includes: establishing an encrypted connection with a host by a network access device using Transmission Control Protocol (TCP); determining by the network access device that packets to be transmitted to the host will be routed via a TCP tunnel client program; sending, by the network access device based on the determination, the packets to the TCP tunnel client program; encrypting, signing, and fragmenting, by the TCP tunnel client program, the packets to produce encrypted packets having instructions for controlling the network device; and sending, by the network access device using TCP, the encrypted packets to a remote endpoint associated with the host.
[0047] In Example 2, the subject matter of Example 1 optionally includes: wherein the network access device is a device having the ability to create a virtual network interface.
[0048] In Example 3, the subject matter of Example 2 optionally includes: wherein the network access device is a switch.
[0049] In Example 4, the subject matter of Example 2 optionally includes: wherein the network access device is a TUN device.
[0050] In Example 5, the subject matter of Example 2 optionally includes: wherein the device includes a virtual IP point-to-point interface having the ability to process network packets and is configured to connect to a host or server running a TCP tunnel program.
[0051] In Example 6, the subject matter of any one of the foregoing examples optionally includes: wherein the network access device TCP tunnel program is configured to connect to a host running a TCP tunnel server program.
[0052] In Example 7, the subject matter of Example 6 optionally includes: wherein, the TCP tunnel server program can only be reached via TCP port 443.
[0053] In Example 8, the subject matter of any of the foregoing examples optionally includes: wherein, the encrypted packets pass through load balancing logic.
[0054] In Example 9, the subject matter of Example 8 optionally includes: wherein, the load balancing logic includes one or more of the following: geography, latency, host health, or host server response time.
[0055] In Example 10, the subject matter of Example 9 optionally further includes: directing the encrypted packets to a specific host running the TCP tunnel server program, and enabling multiple hosts to run the TCP tunnel server program in parallel.
[0056] In Example 11, the subject matter of Example 10 optionally includes: wherein, the TCP tunnel server program is configured to execute on a TCP tunnel server, which includes a cloud-based server or any device capable of creating a virtual network interface.
[0057] Example 12 is a system that includes a network access device, the network access device includes one or more processors and a data storage system communicatively coupled to the one or more processors, wherein, the data storage system includes instructions thereon that, when executed by the one or more processors, cause the one or more processors to: establish an encrypted connection with a host using the Transmission Control Protocol (TCP); determine that packets to be transmitted to the host will be routed via a TCP tunnel client program; based on the determination, send the packets to the TCP tunnel client program; use the TCP tunnel client program to encrypt, sign, and segment the packets to produce encrypted packets that have instructions for controlling the network device; and send the encrypted packets to a remote endpoint associated with the host using TCP.
[0058] In Example 13, the subject matter of Example 12 optionally includes: wherein, the network access device is a device capable of creating a virtual network interface.
[0059] In Example 14, the subject matter of Example 13 optionally includes: wherein, the network access device is a switch.
[0060] In Example 15, the subject matter of Example 13 optionally includes: wherein, the network access device is a TUN device.
[0061] In Example 16, the subject matter of Example 13 optionally includes: wherein the network access device includes a virtual IP point-to-point interface capable of processing network packets and is configured to connect to a host or server running a TCP tunnel server program.
[0062] In Example 17, the subject matter of Example 16 optionally includes: wherein the TCP tunnel server program is configured to execute on a TCP tunnel server including a cloud-based server.
[0063] In Example 18, the subject matter of Example 16 optionally includes: wherein the network access device TCP tunnel program is configured to automatically connect to a host running a TCP tunnel server program.
[0064] In Example 19, the subject matter of any one of Examples 12 to 18 optionally includes: wherein encrypted packets pass through load balancing logic.
[0065] In Example 20, the subject matter of Example 19 optionally includes: wherein the load balancing logic includes one or more of the following: geography, latency, host health, or host server response time.
[0066] Example 21 is at least one machine-readable medium including instructions that, when executed by a processing circuit, cause the processing circuit to perform operations for implementing any one of Examples 1 to 20.
[0067] Example 22 is a device including an apparatus for implementing any one of Examples 1 to 20.
[0068] Example 23 is a system for implementing any one of Examples 1 to 20.
[0069] Example 24 is a method for implementing any one of Examples 1 to 20.
[0070] Language
[0071] Throughout the specification, multiple instances may implement components, operations, or structures described as a single instance. Although individual operations of one or more methods are shown and described as separate operations, one or more of the individual operations may be performed simultaneously and the operations are not required to be performed in the order shown. Structures and functions presented as separate components in an example configuration may be implemented as a combined structure or component. Similarly, structures and functions presented as a single component may be implemented as separate components. These and other variations, modifications, additions, and improvements fall within the scope of the subject matter herein.
[0072] The above detailed embodiments include reference to the accompanying drawings, which form a part of the detailed embodiments. The accompanying drawings illustrate, by way of example, specific embodiments in which the present invention may be practiced. Such embodiments are also referred to herein as "examples". Such examples may include elements other than those shown or described. This application is intended to cover modifications or variations of this subject matter. It should be understood that the above description is illustrative and not restrictive. The scope of this subject matter should be determined with reference to the appended claims and the full scope of equivalents to such claims.
Claims
1. A computer-implemented method for controlling a network device, the method comprising: establishing an encrypted connection with a host by a network access device using the Transmission Control Protocol (TCP); determining by the network access device that a packet to be transmitted to the host will be routed via a TCP tunnel client program; sending the packet to the TCP tunnel client program by the network access device based on the determination; encrypting, signing, and splitting the packet by the TCP tunnel client program to generate an encrypted packet having instructions for controlling a network device; and sending the encrypted packet to a remote endpoint associated with the host by the network access device using the TCP.
2. The method according to claim 1, wherein, the network access device is a device having the ability to create a virtual network interface.
3. The method according to claim 2, wherein, the network access device is a switch.
4. The method according to claim 2, wherein, the network access device is a TUN device.
5. The method according to claim 2, wherein, the device includes a virtual IP point-to-point interface having the ability to process network packets and is configured to connect to a host or server running a TCP tunnel program.
6. The method according to claim 1, wherein, the network access device TCP tunnel program is configured to connect to a host running a TCP tunnel server program.
7. The method according to claim 6, wherein, the TCP tunnel server program can only be reached via TCP port 443.
8. The method according to claim 1, wherein, the encrypted packet passes through load balancing logic.
9. The method according to claim 8, wherein, the load balancing logic includes one or more of the following: geography, latency, host health, or host server response time.
10. The method according to claim 9, further comprising directing the encrypted packet to a specific host running a TCP tunnel server program and enabling multiple hosts to run the TCP tunnel server program in parallel.
11. The method according to claim 10, wherein, the TCP tunnel server program is configured to execute on a TCP tunnel server, the TCP tunnel server including a cloud-based server or any device capable of creating a virtual network interface.
12. A system, comprising: a network access device including one or more processors and a data storage system in communication with the one or more processors, wherein the data storage system includes instructions thereon that, when executed by the one or more processors, cause the one or more processors to: establish an encrypted connection with a host using the Transmission Control Protocol (TCP); determine that a packet to be transmitted to the host will be routed via a TCP tunnel client program; send the packet to the TCP tunnel client program based on the determination; Encrypt, sign, and segment the packet using the TCP tunnel client program to generate an encrypted packet having instructions for controlling a network device; and Send the encrypted packet to a remote endpoint associated with the host using the TCP.
13. The system according to claim 12, wherein the network access device is a device capable of creating a virtual network interface.
14. The system according to claim 13, wherein the network access device is a switch.
15. The system according to claim 13, wherein the network access device is a TUN device.
16. The system according to claim 13, wherein the network access device includes a virtual IP point-to-point interface capable of processing network packets and is configured to connect to a host or server running a TCP tunnel server program.
17. The system according to claim 16, wherein the TCP tunnel server program is configured to execute on a TCP tunnel server including a cloud-based server.
18. The system according to claim 16, wherein the network access device TCP tunnel program is configured to connect to a host running the TCP tunnel server program.
19. The system according to claim 12, wherein the encrypted packet passes through load balancing logic.
20. The system according to claim 19, wherein the load balancing logic includes one or more of the following: geography, latency, host health, or host server response time.